With the release of DeepSeek Harness, the agent business is about to change.

Don't confuse DeepSeek Harness with Claude Code.

When I first saw DeepSeek Harness, only two words came to mind: Is that all?

A simple, somewhat bland dialog box, paired with an equally unremarkable sidebar. At first glance, I even thought I had accidentally opened some unknown, low-quality product; the next second, I began to wonder if DeepSeek simply didn't have the budget for a UI designer position.

To be honest, even if I were to post this front-end interface on social media to join the fun, I couldn't find a single representative screenshot. It lacks the geeky feel of Claude Code's command line interface, the professional IDE vibe of Cursor, and it's nothing like WorkBuddy, which practically slaps every feature onto your face.

Rough is rough, and trying to explain it as "skillful yet unrefined" is just trying to make excuses for DeepSeek. But it wasn't until I opened the model settings page that I realized that my earlier conclusion of "that's it" was indeed a bit too hasty.

In the past, connecting non-native model vendors to Claude Code or Codex typically required modifying configuration files, environment variables, or proxy rules. The configuration formats varied across different tools, leading to complexity that third-party applications like CC Switch emerged to specifically help users manage switching between different coding agents and model vendors.

With DeepSeek Harness, model provider integration is itself made into a plugin. Providers such as the DeepSeek official API, Anthropic, and OpenAI can be directly configured, and company gateways, self-built model services, and other OpenAI API-compatible endpoints can also be integrated as custom providers.

The plug-in approach to model switching only slightly improves convenience, but as you delve deeper, you'll discover that the same rules cover almost all the key components of an Agent: model access is a plug-in, memory is a plug-in, sandbox is a plug-in, storage is a plug-in, and permission approval, context compression, and user interface are also plug-ins. Even the Agent Loop, which was recently touted by various experts, is simply one of the plug-ins that can be loaded and replaced—nothing more.

Seeing this, I realized that this thing is somewhat like "hiding a gem in plain clothes": on the surface it is just a simple chat box, but inside it is a whole set of Agent systems that can be installed, replaced and recombined.

Herein lies the key. DeepSeek Harness doesn't truly deliver the chat window you see here. The chat interface itself is a plugin, and the programming mode is simply a pre-configured set of plugins. By changing this set, the same DeepSeek Harness base can be assembled into agents serving different scenarios.

Therefore, programming ability is just the first reference design presented in this system, and it is definitely not the limit of DeepSeek Harness's capabilities.

Comparing its programming paradigm to Claude Code's Vibe Coding is certainly possible. After all, DeepSeek Harness did indeed utilize its plugin platform to assemble an agent capable of writing code.

What's truly outrageous is that some (pseudo) tech bloggers, after only a few rounds of Vibe Coding, are ready to draw conclusions about the entire DeepSeek Harness.

This is like using Unreal Engine's official modular template game. Lyra Starter GameIt can be compared to Epic's Fortnite, which has been around for many years, in terms of playability.

Lyra allows shooting, team play, and point capture, making it a truly playable shooter, and it's no surprise it loses to Fortnite in reviews. However, Epic Games created Lyra primarily to showcase how character, weapon, skill, online, and UI systems can be disassembled, combined, and reused within the Unreal Engine. From its inception, it was a modular template project for developers to study.

Because Lyra isn't as fun as Fortnite, they declared Unreal Engine worthless; because the first programming agent assembled by DeepSeek Harness wasn't as mature as Claude Code, they declared that this agent platform had no future.

Testing Vibe Coding is perfectly reasonable. The problem lies in using a single sample to generalize about the entire production line.

The target user for this product, 99%, is not you, the reader of this article.

Besides comparing it to Claude Code, there's another misconception: that DeepSeek Harness is being evaluated as a personal software for consumers.

This demonstrates a rather limited understanding: regardless of whether the product, platform, or infrastructure being released, the immediate question is whether it can be installed with one click or if one can leave work immediately. However, the users DeepSeek Harness should truly focus on are agent developers, enterprise IT teams, system integrators, and plugin developers. Ordinary users may end up using products built on DeepSeek Harness every day without even knowing that DeepSeek Harness exists.

What value does plug-in architecture actually bring? A case study of an industry agent procurement should be able to explain this well.

Suppose an insurance company is purchasing a business operations analysis agent. Staff upload policies, premiums, and claims details, which the agent can analyze loss ratios, claim frequency, and identify anomalies. Since the table structure and analysis criteria may change each time, the agent dynamically generates Python or SQL (Structured Query Language) data, then puts it into a sandbox for data cleaning, correlation, and calculation.

Anonymized data was used during the selection phase, and the business department was very satisfied after testing. However, the project was rejected outright by the IT department during the compliance review.

The reasons are very valid: once officially implemented, it's impossible to require employees to anonymize tens of thousands of lines of data one by one each time. Real policy and claims data involves a large amount of personal information, and once sent to the vendor's public cloud sandbox, it falls outside the insurance company's control. Where the data is stored, whether the sandbox can access the public internet, and who has read customer information are all things the company cannot fully control. Furthermore, the vendor's sandbox cannot be integrated into the enterprise's internal IAM (Identity and Access Management) and auditing systems; clearly, data flow is out of control at this point.

The ability is fine, but the compliance is a major problem, so it's a veto.

Following DeepSeek Harness's plug-in approach, salvaging this deal is actually quite simple: the existing insurance analytics workflow can continue to be used, while the execution environment is moved into the enterprise's own VPC (Virtual Private Cloud), along with relevant compliance modifications. The model should also be deployed internally or integrated with an enterprise-grade model service that has passed security audits. In this way, the agent can still run code, but customer data remains within the scope permitted by the enterprise.

In the past, non-compliance with sandboxes often meant that the entire agent suite needed to be redesigned. DeepSeek Harness has streamlined this into a single, replaceable enterprise module. For this insurance company's requirements, the agent provider will first search for a suitable sandbox solution within DeepSeek Harness's plugin ecosystem.

  • If a suitable plugin is found, the vendor can deploy the corresponding execution service into the insurance company's private cloud and then integrate it with the internal IAM and auditing systems. For common enterprise security requirements, this step may mainly involve configuration and integration, without the need to redevelop the entire agent.
  • If existing mature solutions are incompatible with an insurance company's infrastructure, the enterprise IT department can also seek out security vendors or system integrators to customize a dedicated DeepSeek Harness sandbox plugin. This plugin is only responsible for connecting internal data, executing code, and logging operations; it can even remain within the company and its source code does not need to be publicly released.

In this approach, the agent developer is responsible for insurance analytics capabilities, the security vendor provides a compliant execution environment, and the enterprise IT controls the data and permissions. Enterprises can choose the most mature solutions from each party and then assemble them into an agent that meets their specific requirements.

This model fundamentally changes the development paradigm of agents: teams developing legal agents can focus on contract review and legal processes; teams developing financial agents can specialize in optimizing reconciliation, closing, and anomaly detection. General system support such as model adaptation, enterprise memory, sandboxing, and access control systems can be outsourced to more specialized vendors.

From the customer's perspective, enterprises don't necessarily need to rely entirely on a single agent vendor; it's entirely possible to form a joint internal and external development team. Taking the insurance company example again, it can purchase a mature insurance analytics solution, have a security vendor provide a private sandbox, and have its internal IT department handle integration with IAM and business databases. All parties complete the delivery using the same set of plug-in interfaces.

More specific business opportunities will also emerge. In the past, a company that only focused on sandboxes, approvals, or enterprise memory found it difficult to build a business independently based on a single module. In the plug-in ecosystem, as long as one module is professional enough, the product has the opportunity to be directly integrated into a large number of agent products with its own brand.

OpenStack is an open-source cloud computing platform. It manages compute, storage, networking, and authentication using different components, which enterprises then combine to create their own cloud platform as needed. This logic is closer to DeepSeek Harness than Lego. DeepSeek Harness also aims to break down the Agent into a set of specialized modules that can be independently developed, replaced, and delivered.

In the past, developing an agent meant that a company had to complete the system work end-to-end; DeepSeek Harness envisions a future where more companies can simply focus on what they do best and leave the rest to the plugin ecosystem.

What exactly is DeepSeek aiming for by building a plugin ecosystem?

If DeepSeek Harness can truly form a plugin ecosystem, the cost structure of the agent industry will also change.

A sandbox that has passed the security review of financial institutions can simultaneously access different agents of banks, insurance companies, and securities firms; a mature enterprise memory plugin can also be repeatedly invoked by legal, medical, and financial products. Repetitive development that was previously hidden in each project has the potential to become a standard product that can be delivered multiple times.

However, please note that the more open the plugin ecosystem is, the higher the management costs will be.

Plugins may access enterprise data, call internal systems, or even execute code directly. A vulnerability in any plugin could cripple the entire agent suite. Whether it will still function after a version upgrade, and who should be held responsible for conflicts between plugins, will also incur new development costs.

A mature plugin ecosystem will inevitably require security reviews, compatibility testing, version management, and long-term maintenance. Otherwise, so-called openness can easily become simply picking up a bunch of code from GitHub, wrapping it in another layer, and ultimately leaving enterprise customers gambling with the developers.

DeepSeek Harness is currently in Developer Preview. What we can confirm today is that DeepSeek has opened its plugin interface and community portal. Whether it can grow into a truly professional supply chain depends on whether enough developers, enterprise customers, and solution providers are willing to invest in it.

The next question is probably the most crucial part of this article: Why is DeepSeek opening up this entry point for free?

The most obvious answer is data.

Developers worldwide run agents on DeepSeek Harness, DeepSeek conveniently takes the task trajectories, and then uses this data to train the next generation of models. This sounds like the standard script for a "data flywheel," but unfortunately, it doesn't make any technical sense at all.

DeepSeek Harness uses the permissive MIT open-source license, and sessions can be directly stored in local JSONL files or SQLite databases. Although it provides telemetry capabilities based on OpenTelemetry, these are disabled by default; even if actively enabled, the destination of the data is determined by the deployer.

This means that task trajectories generated by users using models such as Claude and OpenAI will not automatically flow into DeepSeek. Even when calling the official DeepSeek API, it can only see the context and related metadata sent to that interface. Local logs not sent to the model, as well as trajectories generated by other models, will not automatically enter the DeepSeek server.

Therefore, describing DeepSeek Harness as a free training data pipeline deployed by DeepSeek is currently poorly supported by evidence. To put it more directly: while this architecture does open up the agent pool, it hasn't yet incidentally unlocked the entire industry's data vault.

What DeepSeek can currently obtain is, first and foremost, a model distribution channel that it controls.

When a model enters the agent market today, strong capabilities are only the first hurdle. How Harness transmits tool calls, handles reasoning, and utilizes context caching all affect the final user experience. If DeepSeek models can only run within Harnesses defined by other vendors, new models may not receive support for a long time, and special protocols may be flattened by general adaptation layers. Even if the model runs fast, it might still be sluggish due to Harness scheduling, and users will still be criticizing DeepSeek.

With DeepSeek Harness, DeepSeek can simultaneously update its official adapter when releasing new models, ensuring that streaming output, reasoning feedback, caching, and token statistics are all optimized in advance. Claude, OpenAI, and other models can still be integrated, and DeepSeek will still compete with them; at least the track for this competition is no longer entirely built by others.

As more and more agent developers adopt DeepSeek Harness, its value will continue to increase. Plugin vendors will proactively make their interfaces compatible, enterprise projects will build implementation experience around it, and new tools will prioritize integration with this system.

At that stage, DeepSeek Harness was no longer just open-source code; it began to have the ability to define Agent interfaces.

Each added sandbox, memory, or industry plugin is like opening another door for DeepSeek models to enter. While it's impossible to guarantee which model will ultimately run inside, DeepSeek at least has the qualification to stand at the door and compete.

These impacts could potentially translate into revenue in the future. Users who ultimately choose the DeepSeek model can generate revenue from computing power; businesses that require official support, proprietary deployments, or plugin certification may also generate new service businesses.

However, as of now, DeepSeek has neither announced a paid plugin market nor demonstrated its intention to directly operate a large number of vertical agents. There is still a long way to go before these possibilities are presented as established strategies.

Based on this, some people assert that DeepSeek will definitely not become a vertical agent; others believe that it plans to first let the fish swim and see which market can make money, and then reap the rewards after the plug-in manufacturers have fattened up the fish.

Both of these scenarios are very vivid and sound quite tempting. The problem is that the fox's tail has only just been revealed, and everyone has already started arguing about whether it's Nick or Lina Bell who's coming... Don't rush, what if it's Daji inviting you to play together?

OpenAI has already optimized its models specifically for financial workflows, launched ChatGPT for Excel, and integrated with professional financial data sources such as FactSet, LSEG, and S&P Global. This is sufficient proof that once a model company identifies a valuable vertical market, it is entirely possible to continue moving towards the application layer. However, despite choosing this path, OpenAI has still not been able to announce a business plan for DeepSeek.

DeepSeek may launch its own agent product in the future, or it may focus on developing its model and infrastructure in the long term, or it may adopt completely different strategies in different markets. The only thing we can confirm today is that DeepSeek Harness has secured a location closer to the agent entry point for DeepSeek.

However, the real skill in the platform wars is never just about securing the entrance, but also about getting others to join in expanding that entrance.

DeepSeek Harness allows developers to replace models, sandboxes, memories, tools, and interfaces, and also allows enterprises to keep plugins on their own servers. DeepSeek does not require all agents to run DeepSeek models, nor does it require plugin developers to hand over source code and user data. It provides a common foundation on which other companies can develop products, provide services, and even build their own businesses.

This will certainly bring DeepSeek model distribution, API influence, and business options. But these benefits share a common premise: that developers actually have the choice.

If DeepSeek rushes to charge every plugin a toll or places its own model in an irreplaceable central position, the ecosystem will quickly lose its appeal. It must strike a balance between control and openness, ensuring other participants can genuinely profit from the platform, in order to gain greater industry influence.

This is precisely what makes DeepSeek Harness so commendable.

DeepSeek has already made its models open-source, and now it's opening up the environment in which those models work. It's giving developers some power to define agents, and also leaving opportunities for businesses to operate around agents to the entire industry.

One final suggestion: Liang Sheng might as well give it a try. It seems like the OpenAI trademark is hopeless, so why not register the phrase "DeepSeek, The Real Open AI"?

Author

  • ZAI科技站点图标

    From an engineer's perspective, observe AI, developers, and the technology industry.